Vulnerability

CVE-2020-24587

Component: WIFI
Location: OS
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

2.6

Severity (Android)

N/A

Chipsets

17

Devices

658

Affected Hardware

NameAlso known asManufacturer
MSM8208
Snapdragon 208
Qualcomm
MSM8917
Snapdragon 425
Qualcomm
MSM8940
Snapdragon 435
Qualcomm
MSM8952
Snapdragon 617
Qualcomm
MSM8953
Snapdragon 625
Qualcomm
SDM630
Snapdragon 630
Qualcomm
SDM636
Snapdragon 636
Qualcomm
MSM8956
Snapdragon 650
Qualcomm
MSM8976
Snapdragon 652
Qualcomm
SM6150
Snapdragon 675
Qualcomm
17 of 17 row(s) shown.

Rows per page

Page 1 of 2

Timeline

Introduced (est):
Jan 1, 2014
Reported:
Dec 13, 2020
Advisory Published:
Aug 2, 2021
CVE Published:
May 11, 2021
Android Patch Level:
Oct 2021
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter